CRITICAL

CVE-2026-83548

Sonicwall Sma8200v 2026-09-01 CVSS v3.1
CVSS
10
KEV

Description

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

Summary dbcve.org

A pre-authentication Server-Side Request Forgery (SSRF) vulnerability exists in the SMA1000 Appliance Work Place interface. The flaw stems from an unintended alternate access path that allows remote unauthenticated attackers to make the appliance perform arbitrary HTTP requests to internal or external resources, potentially exposing sensitive internal functionality and enabling further unauthorized operations.

Mitigation

Apply vendor-supplied patches for SMA1000 to remediate the alternate access path; if no patch is available, restrict network access to the Work Place interface using firewall rules or disable untrusted access paths until a fix is deployed.

Weakness (CWE)

CWE-441
CWE-918 Server-Side Request Forgery (SSRF)

EPSS Score

4.67%
Probability of exploitation in next 30 days
91.3th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE